Re: [Add] WG Adoption Call draft-reddy-add-enterprise-split-dns

mohamed.boucadair@orange.com Fri, 13 May 2022 08:58 UTC

Return-Path: <mohamed.boucadair@orange.com>
X-Original-To: add@ietfa.amsl.com
Delivered-To: add@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 840FEC157B45 for <add@ietfa.amsl.com>; Fri, 13 May 2022 01:58:40 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -7.098
X-Spam-Level:
X-Spam-Status: No, score=-7.098 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_HI=-5, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, UNPARSEABLE_RELAY=0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=orange.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id KX1dpswRoylJ for <add@ietfa.amsl.com>; Fri, 13 May 2022 01:58:36 -0700 (PDT)
Received: from relais-inet.orange.com (relais-inet.orange.com [80.12.66.40]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id A1095C14EB1F for <add@ietf.org>; Fri, 13 May 2022 01:58:36 -0700 (PDT)
Received: from opfedar03.francetelecom.fr (unknown [xx.xx.xx.5]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits)) (No client certificate requested) by opfedar27.francetelecom.fr (ESMTP service) with ESMTPS id 4L02cV4wt1z2xvt for <add@ietf.org>; Fri, 13 May 2022 10:58:34 +0200 (CEST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=orange.com; s=ORANGE001; t=1652432314; bh=c9wErxuICb9xRXL4UzhSqU/+9pprPtvnhBieP6R2CO4=; h=From:To:Subject:Date:Message-ID:Content-Type: Content-Transfer-Encoding:MIME-Version; b=wag7ewjXcrl5XiVIczczQqhsjrwsAaLaZiWDLWt/0H+gdqjm8+huPY1/nr13PqXdr 5Sl5qN7cByWAXQkjBW2GEz45Od2+oE11sP+Qaw6oF3POj64AM8l/3WpDL3S+CiKYCN w0mkLHFAFDrF3MTXBRFydj21t4Cqy7AWgOTOyxLY+kIJQ2YMhyTVD0pKOMfO88DVLC e67gJMppLyeTEcq5WvskOnylFgQGdahRFSFXPiNMEsQuEB5P00pbncIEHW01zCThnD wngNdl+aqX/JUkreLHbVYlfnHcvu6KO8nYTnt5Wq9eqn7xNzVS0sfiC3azoFW6edPj cG0JCeNRBimgg==
From: mohamed.boucadair@orange.com
To: ADD Mailing list <add@ietf.org>
Thread-Topic: [Add] WG Adoption Call draft-reddy-add-enterprise-split-dns
Thread-Index: AQHYYKiFZU8SqNiAaUeVfv0/InhPc60Qoi8AgAARH4CAC8/LgIAAJAIA///lpMA=
Content-Class:
Date: Fri, 13 May 2022 08:58:34 +0000
Message-ID: <887_1652432314_627E1DBA_887_94_1_7b812726035a481abb7b5721d3912999@orange.com>
References: <BYAPR11MB3111FD2D0FF61231304A5F3DEAC29@BYAPR11MB3111.namprd11.prod.outlook.com> <CAHbrMsAcpHFon+JS9jsLdqANt+1FmkA_VDAwW4PSUDMJwtbavA@mail.gmail.com> <14b56185-4fe3-8e4b-adcf-22ddb624329@nohats.ca> <6091dcb9-0d91-6666-2c3f-ae8da960242b@lear.ch> <5D01FBF6-6F23-4414-AA10-3CD4D65D6DE2@telefonica.com>
In-Reply-To: <5D01FBF6-6F23-4414-AA10-3CD4D65D6DE2@telefonica.com>
Accept-Language: fr-FR, en-US
Content-Language: fr-FR
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
msip_labels: MSIP_Label_07222825-62ea-40f3-96b5-5375c07996e2_Enabled=true; MSIP_Label_07222825-62ea-40f3-96b5-5375c07996e2_SetDate=2022-05-13T08:54:44Z; MSIP_Label_07222825-62ea-40f3-96b5-5375c07996e2_Method=Privileged; MSIP_Label_07222825-62ea-40f3-96b5-5375c07996e2_Name=unrestricted_parent.2; MSIP_Label_07222825-62ea-40f3-96b5-5375c07996e2_SiteId=90c7a20a-f34b-40bf-bc48-b9253b6f5d20; MSIP_Label_07222825-62ea-40f3-96b5-5375c07996e2_ActionId=3fc50668-0672-4ec9-88ec-831d628a31b8; MSIP_Label_07222825-62ea-40f3-96b5-5375c07996e2_ContentBits=0
x-originating-ip: [10.115.26.50]
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64
MIME-Version: 1.0
Archived-At: <https://mailarchive.ietf.org/arch/msg/add/VN6LCxoY3nVutMlV1svRledUelw>
Subject: Re: [Add] WG Adoption Call draft-reddy-add-enterprise-split-dns
X-BeenThere: add@ietf.org
X-Mailman-Version: 2.1.34
Precedence: list
List-Id: Applications Doing DNS <add.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/add>, <mailto:add-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/add/>
List-Post: <mailto:add@ietf.org>
List-Help: <mailto:add-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/add>, <mailto:add-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 13 May 2022 08:58:40 -0000

Hi all, 

Definitely agree with Diego and Eliot. 

I support adopting this document as a starting point.  

Cheers,
Med

> -----Message d'origine-----
> De : Add <add-bounces@ietf.org> De la part de Diego R. Lopez
> Envoyé : vendredi 13 mai 2022 10:29
> À : Eliot Lear <lear@lear.ch>; Paul Wouters <paul@nohats.ca>;
> bemasc@google.com
> Cc : ADD Mailing list <add@ietf.org>
> Objet : Re: [Add] WG Adoption Call draft-reddy-add-enterprise-
> split-dns
> 
> Hi,
> 
> I take advantage of Eliot's statement to essentially agree with
> him and support adoption. There are a few aspects related to
> choices and enterprise environments I think would require more
> discussion, but this is what adoption is for...
> 
> Be goode,
> 
> --
> "Esta vez no fallaremos, Doctor Infierno"
> 
> Dr Diego R. Lopez
> Telefonica I+D
> https://www.linkedin.com/in/dr2lopez/
> 
> e-mail: diego.r.lopez@telefonica.com
> Mobile:  +34 682 051 091
> ----------------------------------
> 
> On 13/05/2022, 10:20, "Add on behalf of Eliot Lear" <add-
> bounces@ietf.org on behalf of lear@lear.ch> wrote:
> 
>     Hi,
> 
>     On 05.05.22 21:57, Paul Wouters wrote:
>     > The only real solution I see is one similar to the IKEv2
> split-DNS case,
>     > one where there is basically an authenticated and authorized
>     > provisioning step that enables the user to join an
> "enterprise network"
>     > wich can demand all or a subnet of DNS traffic which the
> user is required
>     > to opt-in to. And even that is tricky when a user is kinda
> forced to
>     > accept to get any connectivity, say in a hotel or coffeeshop
> (or
>     > repressive regime)
> 
>     I think you are aiming at the fundamental problem, Paul: is
> there a way
>     for the user to decide who to trust.  Ben's pointed out the UX
> problems
>     with answering that question.  For enterprise assets that
> clearly has to
>     be the enterprise.  The only question really is how to
> bootstrap trust
>     in the enterprise.  Any draft trying to address split DNS has
> to assume
>     that has happened.  That part can't be in scope here.
> 
>     What this or any draft has to do is be a bit clearer in
> stating that and
>     then show how that bootstrapping of trust is leveraged to
> address split
>     DNS, either via resolver selection at a gross or fine level,
> or through
>     other means.  Right now I think it is trying to demonstrate
> that through
>     multiple mechanisms, and that is what is making things rather
> hard to
>     follow.  That's because there is no one-size-fits-all solution
> because
>     enterprises come in many shapes and forms.  To some, leaking a
> modest
>     amount of NS records is okay.  The pollution argument you
> raise is only
>     relevant in as much as domains outside the enterprise control
> would be
>     polluted.  If that's not the case, then it's a matter for an
> enterprise,
>     and nobody else's business.
> 
>     So I support adoption of this draft, but I do think it needs a
> lot more
>     work to be clearer on the bootstrapping that is occurring.
> 
>     Eliot
> 
> 
> 
> 
> ________________________________
> 
> Este mensaje y sus adjuntos se dirigen exclusivamente a su
> destinatario, puede contener información privilegiada o
> confidencial y es para uso exclusivo de la persona o entidad de
> destino. Si no es usted. el destinatario indicado, queda
> notificado de que la lectura, utilización, divulgación y/o copia
> sin autorización puede estar prohibida en virtud de la legislación
> vigente. Si ha recibido este mensaje por error, le rogamos que nos
> lo comunique inmediatamente por esta misma vía y proceda a su
> destrucción.
> 
> The information contained in this transmission is confidential and
> privileged information intended only for the use of the individual
> or entity named above. If the reader of this message is not the
> intended recipient, you are hereby notified that any
> dissemination, distribution or copying of this communication is
> strictly prohibited. If you have received this transmission in
> error, do not read it. Please immediately reply to the sender that
> you have received this communication in error and then delete it.
> 
> Esta mensagem e seus anexos se dirigem exclusivamente ao seu
> destinatário, pode conter informação privilegiada ou confidencial
> e é para uso exclusivo da pessoa ou entidade de destino. Se não é
> vossa senhoria o destinatário indicado, fica notificado de que a
> leitura, utilização, divulgação e/ou cópia sem autorização pode
> estar proibida em virtude da legislação vigente. Se recebeu esta
> mensagem por erro, rogamos-lhe que nos o comunique imediatamente
> por esta mesma via e proceda a sua destruição
> --
> Add mailing list
> Add@ietf.org
> https://www.ietf.org/mailman/listinfo/add

_________________________________________________________________________________________________________________________

Ce message et ses pieces jointes peuvent contenir des informations confidentielles ou privilegiees et ne doivent donc
pas etre diffuses, exploites ou copies sans autorisation. Si vous avez recu ce message par erreur, veuillez le signaler
a l'expediteur et le detruire ainsi que les pieces jointes. Les messages electroniques etant susceptibles d'alteration,
Orange decline toute responsabilite si ce message a ete altere, deforme ou falsifie. Merci.

This message and its attachments may contain confidential or privileged information that may be protected by law;
they should not be distributed, used or copied without authorisation.
If you have received this email in error, please notify the sender and delete this message and its attachments.
As emails may be altered, Orange is not liable for messages that have been modified, changed or falsified.
Thank you.